57,566 vulnerabilities published in 2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.
A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-
A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the
Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network pos
An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configura
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not vali
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to fo
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS stat
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not se
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability chec
The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied paramete
The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action befo
The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token i
The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and
XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Si
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm,
@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.cont
OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/cl
go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202
Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts throu
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Hu
In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. Th
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attacker
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows at
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the con
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verifi
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all
Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting,
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namesp
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). Th
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP
Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Admin
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogi
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 all
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to de
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using i
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated us
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started